meal-order-manager/terraform/vpc.tf
Adam Moussa 3efff5e784
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
fix(infra): share the afterhours VPC in prod (PLAT-215) (#203)
* fix(infra): share the afterhours VPC when existing_vpc_id is set

Prod is at the account VPC quota, so the v1.0.0 apply destroyed Lambda/API Gateway then failed on CreateVpc. Skip creating a sixth VPC when the workspace supplies afterhours subnets.

* style(test): format the VPC terraform assertion for ruff
2026-09-21 21:15:47 +00:00

110 lines
2.5 KiB
HCL

data "aws_availability_zones" "available" {
count = local.manage_vpc ? 1 : 0
state = "available"
}
data "aws_vpc" "existing" {
count = local.manage_vpc ? 0 : 1
id = var.existing_vpc_id
}
data "aws_subnet" "existing_public" {
for_each = toset(var.existing_public_subnet_ids)
id = each.value
}
resource "aws_vpc" "this" {
count = local.manage_vpc ? 1 : 0
cidr_block = local.vpc_cidr
enable_dns_support = true
enable_dns_hostnames = true
tags = {
Name = "${local.project}-vpc"
}
# First apply updates the live hcptf apply role before CreateVpc.
depends_on = [
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
aws_iam_role_policy.hcptf_apply_ec2,
]
}
resource "aws_internet_gateway" "this" {
count = local.manage_vpc ? 1 : 0
vpc_id = aws_vpc.this[0].id
tags = {
Name = "${local.project}-igw"
}
}
resource "aws_subnet" "public" {
count = local.manage_vpc ? length(local.public_subnet_cidrs) : 0
vpc_id = aws_vpc.this[0].id
cidr_block = local.public_subnet_cidrs[count.index]
availability_zone = data.aws_availability_zones.available[0].names[count.index]
map_public_ip_on_launch = true
tags = {
Name = "${local.project}-public-${count.index}"
}
}
resource "aws_route_table" "public" {
count = local.manage_vpc ? 1 : 0
vpc_id = aws_vpc.this[0].id
tags = {
Name = "${local.project}-public"
}
}
resource "aws_route" "public_default" {
count = local.manage_vpc ? 1 : 0
route_table_id = aws_route_table.public[0].id
destination_cidr_block = "0.0.0.0/0"
gateway_id = aws_internet_gateway.this[0].id
}
resource "aws_route_table_association" "public" {
count = local.manage_vpc ? length(local.public_subnet_cidrs) : 0
subnet_id = aws_subnet.public[count.index].id
route_table_id = aws_route_table.public[0].id
}
locals {
vpc_id = local.manage_vpc ? aws_vpc.this[0].id : data.aws_vpc.existing[0].id
public_subnet_ids = local.manage_vpc ? aws_subnet.public[*].id : var.existing_public_subnet_ids
}
moved {
from = aws_vpc.this
to = aws_vpc.this[0]
}
moved {
from = aws_internet_gateway.this
to = aws_internet_gateway.this[0]
}
moved {
from = aws_route_table.public
to = aws_route_table.public[0]
}
moved {
from = aws_route.public_default
to = aws_route.public_default[0]
}
moved {
from = data.aws_availability_zones.available
to = data.aws_availability_zones.available[0]
}